# Saved two hours. Cost four days.

> Licence risk compounds with time, not size.

- **Format:** short video, 9 steps, ~51 seconds
- **Topic:** AI agents for dependency, licence, copyright and privacy compliance — a package added to save two hours costs four days to remove five months later, and how import counts, a written reason per package, a deny list on the resolved tree and a data inventory catch each risk on the day it arrives.
- **Author:** Suthahar Jegatheesan (MSDEVBUILD)
- **Category:** AI · AI
- **Published:** 2026-09-04
- **Tags:** opensource, licensing, flutter, privacy, aiagents, compliance, devsecops, msdevbuild
- **Canonical URL:** https://blog.msdevbuild.com/shorts/ai-supply-chain-agents-two-hours-four-days/

---
## What you'll learn

- Why a dependency gets more expensive every week
- How to find packages nobody imports
- Why the licence check belongs in a hook

## Understand it one step at a time

### 1. One line, two hours saved

A package solves an immediate problem. Nobody reviews a pubspec line.

### 2. It spreads

Already there, so it gets imported in three features.

### 3. A denied licence

Eleven days before launch, the licence turns out to be one the store build cannot ship.

### 4. Count the imports

For each declared package: how many files in lib/ import it?

### 5. uuid: zero files

docs/dependencies.md still has a reason for it. The code moved on.

### 6. A reason per package

pre-commit: a new package needs a row in docs/dependencies.md.

### 7. Deny list on the whole tree

pre-push: denied licences in the resolved tree. Transitive counts.

### 8. Caught on the day

The same package now fails the push the day it is added, while it is in one file.

### 9. Two hours on day one

A reason per package, a deny list on the tree, a source per asset, an inventory for privacy.

---

## The takeaway

**Two hours on day one.**

Licence risk compounds with time, not with size.
